# Chatips Privacy Policy
**Effective date:** 9 September 2026
**Version:** 1.1-beta
**Operator:** Ellen . Lee, trading as Chatips
**Contact:** [email protected]
Chatips is an independent customer-messaging service. It is not affiliated with, endorsed by, or an official product of Chatwoot, Inc.
This Policy explains how we handle personal data during the **free public testing** of Chatips. If this Policy conflicts with a translation, the **English** version applies. Singapore law, including the Personal Data Protection Act 2012 (**PDPA**), is our primary privacy framework.
## 1. Who we are
We operate Chatips as an individual. Application servers are located in **Singapore**. You can contact us at **[email protected]**.
Notices for open-source software we use are published in the Chatips application (licence and third-party notices pages). Those notices are not part of this Policy.
There are two kinds of people whose data may appear on Chatips:
– **Account users** (you and your teammates who sign up). For this data, we are the **organisation** that decides how it is used to run the service.
– **End customers** (people who message you via the website widget, WhatsApp, Telegram, email, or similar). That content belongs to **your** business. We act as a **data intermediary** and process it on your instructions to provide the service.
If you embed the Chatips widget or connect a messaging channel, **you** must tell your own customers how you use Chatips and obtain any consent required by law in Singapore, Malaysia, Indonesia, Vietnam, Thailand, or any other country where you use the service.
Authorised operators of Chatips may access workspace data where reasonably needed to provide or secure the service, to keep the test reliable, to prevent abuse, to handle support requests, to operate optional platform diagnostics described below, or to comply with law.
## 2. Data we collect
**Account and security**
– Name-related account details, email address, password (stored hashed), optional Google sign-in, and multi-factor authentication data
– hCaptcha responses at sign-up, to reduce abuse
– Login session cookies and security logs (including IP address, approximate time, and similar technical data)
**Your workspace**
– Inboxes, teammates, contacts, conversations, notes, tags, canned replies, automation, help-center articles, surveys, and similar configuration
– Files and **voice notes** attached to conversations
– Optional transcripts of voice messages, and optional AI-generated replies or suggestions (including Captain), if you turn those features on
**End-customer and widget data** (processed for you)
– Messages, contact attributes you store, and attachments
– Widget cookies or similar identifiers (for example a conversation identifier) so a visitor can continue a chat
– Optional IP-based location, **only if** we enable it for the platform **and** you enable it for your account (it is off by default)
We do not currently collect payment card details. **The service is free during this test.** Do not send national ID numbers, payment card data, or health records through Chatips.
## 3. Why we use the data
– To create and secure your account
– To deliver conversations, files, voice notes, and notifications
– To operate optional AI features you enable (including speech-to-text)
– To prevent spam, abuse, and attacks
– To keep the test running and reasonably reliable
– To meet legal requests we cannot lawfully refuse
We do **not** sell personal data.
We do **not** use your workspace content or end-customer conversations to train our own models. Third-party AI providers may have their own training and retention rules; those rules apply to data sent to them. If you connect your own API key, you are also responsible for that provider’s terms.
Under the PDPA, we rely on the bases available to us as an organisation, including that the collection, use, or disclosure is needed to provide the service you request, and other bases permitted by law. For end-customer data, **you** must have a lawful basis to instruct us to process it.
## 4. Cookies and similar technology
– **Dashboard:** session cookies so you stay signed in.
– **Website widget:** cookies or local storage on your customers’ browsers so a chat can resume. These may be set in a third-party context on **your** website. You are responsible for any notice or consent your site needs.
## 5. AI, voice, storage, and other parties
If you use Captain, transcription, or similar features, message text or audio may be sent to model or embedding providers we configure (currently including DeepSeek for language models, and an embedding host we configure for models such as BAAI/bge-m3), or to a provider whose API key you connect. Those providers process the data to return a transcript, vector, or reply. Treat voice notes as potentially sensitive.
If we enable platform LLM tracing, traces (which may include prompts, outputs, and related metadata) may be sent to an observability provider (currently Langfuse) so we can operate and review platform-wide model usage. Tenants do not have a tenant-facing tracing console.
Other parties who may process data to run the service include:
– Hosting and related infrastructure in Singapore
– Cloudflare, including object storage (R2) and content delivery for files and recordings
– hCaptcha
– Optional Google sign-in
– Google, to the extent you email us at a Gmail address
– Messaging providers you connect (WhatsApp, Telegram, Twilio, email, and similar)
– Optional geolocation database providers (for example MaxMind), if IP lookup is enabled
Some of these parties are outside Singapore. We use contracts or comparable safeguards where required. Using Chatips means account data and, where you send it, customer conversation data may be transferred to those parties.
Channel providers (Meta, Telegram, Twilio, Google, and others) have their own terms. We do not control their platforms.
## 6. Retention, export, access, correction, and deletion
We keep data while your account is active and as needed to operate the test, including backups for a limited period.
When this public test ends, or if your account is closed, you may request an export of your workspace data in a commonly used format by emailing **[email protected]**. We will aim to provide the export **within 30 days** (or tell you if we need more time because the request is complex). After the test ends or the account is closed, and after a short period to allow export, we may delete remaining service data, except what we must keep for security, dispute, or legal reasons (for example limited logs).
You may also request access, correction, or deletion of **your account** data at the same email. We will aim to respond **within 30 days**. Requests about **end-customer** chats should first go to the business that collected them (the Chatips account owner). If you cannot reach them, contact us and we will help where we reasonably can as a data intermediary.
## 7. Data incidents
If we determine that a data incident must be notified under applicable law (including the PDPA), we will notify the Personal Data Protection Commission and affected individuals as required, and we will notify affected account owners where it is appropriate and lawful to do so.
## 8. Children
Chatips is for businesses and their teams, not for children. Do not use the service to collect data from children.
## 9. Security
We use HTTPS, hashed passwords, optional MFA, and access controls. No method of transmission or storage is completely secure. During a free test, please use dummy or non-sensitive examples where you can.
## 10. Changes
We may update this Policy as the test and the product change. The “Effective date” will change. Material changes will be posted on this page and, where appropriate, notified by email or in the product.
## 11. Complaints
Contact **[email protected]**. If you are in Singapore, you may also contact the Personal Data Protection Commission (PDPC) if you are not satisfied with our response.